Windows Process Creation: Node.js Executions from Adobe Creative Cloud

Flags Windows executions of Adobe Creative Cloud’s bundled node.exe, excluding typical JS resource paths.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Max Altgelt (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-04-06
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies when a Windows process is launched using Node.js packaged within the Adobe Creative Cloud installation. Attackers can use bundled runtimes to execute scripts from within legitimate software directories, helping blend execution into normal system activity. The detection relies on process creation telemetry that captures the executable path and command line, specifically matching the Creative Cloud node.exe location while excluding command lines that indicate Adobe Creative Cloud JavaScript resource usage.

Related detections9 linkedT1059.007 — drag to rearrange
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious Script Host Execution of Decoy-Named JavaScript Dropper (PS1Bot)
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Script Host Spawning PowerShell With Bypass And Hidden Execution
Possible React2Shell CVE-2025-55182 Prototype Pollution Exploitation
Suspicious Node.js Script Execution from AppData Roaming
Possible Reflected XSS via cPanel cpanelwebcall Endpoint CVE-2023-29489
Suspicious Code Compilation via Aspnet_compiler LOLBIN (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Windows Process Creation: Node.js Executions from Adobe Creative Cloud
Pivot detection · T1059.007 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.